M365PP-003: Tenant isolation settings

Plataforma
Entra ID / M365
Categoría
Power Platform Security
Severidad
High
Pilar de Zero Trust
Applications & Workloads (peso 2)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Power Platform tenant isolation controls whether connectors in your tenant can establish connections to other Azure AD tenants, and whether other tenants can connect to yours. Without tenant isolation, users can create flows and apps that connect to external organizations' data sources, and external organizations can build automations that access your tenant's resources. Enabling tenant isolation prevents unauthorized cross-tenant data flows that could result in data leakage or supply chain compromise.

Valor recomendado

Tenant isolation enabled with inbound and outbound restrictions; allow-listed exceptions only for approved partner tenants

Remediación

Enable Power Platform tenant isolation in the Power Platform admin center to restrict both inbound and outbound cross-tenant connections by default. Configure an allow list of specific trusted partner tenant IDs that require cross-tenant connectivity for legitimate business scenarios. Review the allow list quarterly to remove tenants that no longer require cross-tenant access and monitor the audit logs for any cross-tenant connection attempts that are being blocked by the isolation policy.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de M365PP-003
EscenarioVeredicto esperado
cleanPASS
known-badFAIL
throttledNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
MS.POWERPLATFORM.3.1v1, MS.POWERPLATFORM.3.2v1
NIST SP 800-53
AC-20
CIS M365 Benchmark
9.3